Lucene search

K
cveMitreCVE-2005-0331
HistoryMay 02, 2005 - 4:00 a.m.

CVE-2005-0331

2005-05-0204:00:00
mitre
web.nvd.nist.gov
38
cve-2005-0331
winrar
directory traversal
vulnerability
remote attackers
arbitrary files

CVSS2

2.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:N/I:P/A:N

AI Score

7.1

Confidence

Low

EPSS

0.003

Percentile

69.3%

Directory traversal vulnerability in WinRAR 3.42 and earlier, when the user clicks on the ZIP file to extract it, allows remote attackers to create arbitrary files via a … (triple dot) in the filename of the ZIP file.

Affected configurations

Nvd
Node
rarlabwinrarMatch3.0.0
OR
rarlabwinrarMatch3.10
OR
rarlabwinrarMatch3.10_beta3
OR
rarlabwinrarMatch3.10_beta5
OR
rarlabwinrarMatch3.11
OR
rarlabwinrarMatch3.20
OR
rarlabwinrarMatch3.40
OR
rarlabwinrarMatch3.41
OR
rarlabwinrarMatch3.42
VendorProductVersionCPE
rarlabwinrar3.0.0cpe:2.3:a:rarlab:winrar:3.0.0:*:*:*:*:*:*:*
rarlabwinrar3.10cpe:2.3:a:rarlab:winrar:3.10:*:*:*:*:*:*:*
rarlabwinrar3.10_beta3cpe:2.3:a:rarlab:winrar:3.10_beta3:*:*:*:*:*:*:*
rarlabwinrar3.10_beta5cpe:2.3:a:rarlab:winrar:3.10_beta5:*:*:*:*:*:*:*
rarlabwinrar3.11cpe:2.3:a:rarlab:winrar:3.11:*:*:*:*:*:*:*
rarlabwinrar3.20cpe:2.3:a:rarlab:winrar:3.20:*:*:*:*:*:*:*
rarlabwinrar3.40cpe:2.3:a:rarlab:winrar:3.40:*:*:*:*:*:*:*
rarlabwinrar3.41cpe:2.3:a:rarlab:winrar:3.41:*:*:*:*:*:*:*
rarlabwinrar3.42cpe:2.3:a:rarlab:winrar:3.42:*:*:*:*:*:*:*

CVSS2

2.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:N/I:P/A:N

AI Score

7.1

Confidence

Low

EPSS

0.003

Percentile

69.3%

Related for CVE-2005-0331